Weekend Sale Special - 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: my75ex

Home > Fortinet > Fortinet Network Security Expert > NSE5_FSW_AD-7.6

NSE5_FSW_AD-7.6 Fortinet NSE 5 - FortiSwitch 7.6 Administrator Question and Answers

Question # 4

When Dynamic Host Configuration Protocol (DHCP) snooping is enabled on a FortiSwitch VLAN, which two statements are true? (Choose two answers)

A.

DHCP replies are accepted only on trusted ports.

B.

DHCP snooping blocks all unicast traffic.

C.

Option 82 can be inserted into DHCP requests.

D.

DHCP requests are dropped if sent from trusted ports.

Full Access
Question # 5

Refer to the exhibit.

The profile shown in the exhibit is assigned to a group of managed FortiSwitch ports, and these ports are connected to endpoints which are powered by PoE.

Which configuration action can you perform on the LLDP profile to cause these endpoints to exchange PoE information and negotiate power with the managed FortiSwitch?

A.

Create new a LLDP-MED application type to define the PoE parameters.

B.

Assign a new LLDP profile to handle different LLDP-MED TLVs.

C.

Define an LLDP-MED location ID to use standard protocols for power.

D.

Add power management as part of LLDP-MED TLVs to advertise.

Full Access
Question # 6

Refer to the diagnostic output:

Two entries in the exhibit show that the same MAC address has been used in two different VLANs. Which MAC address is shown in the above output?

A.

It is a MAC address of FortiLink interface on FortiGate.

B.

It is a MAC address of a switch that accepts multiple VLANs.

C.

It is a MAC address of an upstream FortiSwitch.

D.

It is a MAC address of FortiGate in HA configuration.

Full Access
Question # 7

Refer to the exhibits.

All three FortiSwitch-connected ports are configured in VLAN 10. FortiGate acts as the Dynamic Host Configuration Protocol (DHCP) server and is connected to a DHCP snooping trusted trunk port. PC1 and PC2 are connected to ports configured as untrusted for Dynamic ARP Inspection (DAI), and no static bindings are configured in the IP source guard (IPSG) database. PC2 is compromised and attempts to spoof the FortiGate IP address by sending forged Address Resolution Protocol (ARP) replies with its own MAC address. What will FortiSwitch do with the ARP packets from PC2? (Choose one answer)

A.

Forward the ARP replies because there are no IPSG bindings blocking them.

B.

Accept the ARP replies because the VLAN has DAI enabled and FortiGate is a trusted DHCP server.

C.

Forward the ARP replies to all VLAN 10 ports because DAI is only active on trusted ports.

D.

Drop the ARP replies because they fail DAI validation against the DHCP snooping database.

Full Access
Question # 8

You are designing a FortiSwitch backbone where every FortiSwitch device must connect to every other FortiSwitch for maximum redundancy. To maintain connectivity while preventing loops, which protocol or feature must you configure on the switches? (Choose one answer)

A.

Multichassis link aggregation group (MCLAG)

B.

Spanning Tree Protocol (STP)

C.

Full mesh high availability (HA)

D.

Link aggregation group (LAG)

Full Access
Question # 9

What happens if FortiSwitch fails to discover either FortiEdge Cloud or a FortiGate with FortiLink?

A.

It switches to FortiLink mode by default.

B.

It remains in local management mode.

C.

It requires manual reimaging.

D.

It disables auto-network.

Full Access
Question # 10

Which statement about the quarantine VLAN on FortiSwitch is true?

A.

Quarantine VLAN has no DHCP server

B.

Users who fail 802.1X authentication can be placed on the quarantine VLAN.

C.

It is only used for quarantined devices if global setting is set to quarantine by VLAN.

D.

FortiSwitch can block devices without configuring quarantine VLAN to be part of the allowed VLANs.

Full Access
Question # 11

Refer to the exhibit.

You just connected three FortiSwitch devices:Core-1,Core-2, andAccess-1. Core-1 and Core-2 both connect to Access-1 for redundancy. All switches are managed by FortiGate, which uses port4 as the FortiLink interface. After you enable the uplink ports on Core-2, you notice that port3 on Access-1 enters the Discarding STP state. What is the most likely cause of this behavior? (Choose one answer)

A.

Bridge Protocol Data Unit (BPDU) Guard is enabled, which shuts down the port after it receives BPDUs.

B.

Access-1 is not authorized by FortiGate.

C.

Core-2 has the lowest bridge priority.

D.

FortiGate is not running Spanning Tree Protocol (STP) on the FortiLink interface.

Full Access
Question # 12

Which two statements about DHCP snooping enabled on a FortiSwitch VLAN are true? (Choose two.)

A.

Enabling DHCP snooping on a FortiSwitch VLAN ensures requests and replies are seen by all DHCP servers.

B.

switch-controller-dhcp-snooping-verify-mac verifies the destination MAC address to protect against DHCP exhaustion attacks.

C.

By default, all FortiSwitch ports are set to forward client DHCP requests to untrusted ports.

D.

Settings related to DHCP option 82 are only configurable through the CLI

Full Access
Question # 13

Which LLDP-MED Type-Length-Values does FortiSwitch collect from endpoints to track network devices and determine their characteristics?

A.

Network policy

B.

Power management

C.

Location

D.

Inventory management

Full Access
Question # 14

(Full question statement start from here)

You enable Dynamic Host Configuration Protocol (DHCP) snooping on a VLAN and configure a FortiSwitch port astrustedfor DHCP snooping. What additional step is required to configure the port as trusted forDynamic ARP Inspection (DAI)? (Choose one answer)

A.

Manually set the port as trusted for DAI through the CLI.

B.

DAI implicitly trusts the port.

C.

Enable IP Source Guard (IPSG) on the port.

D.

Enable static MAC learning on the port.

Full Access
Question # 15

Refer to the exhibit.

The security port policy is configured as shown in the exhibit. Which behavior occurs if a device connected to the port that does not support 802.1X? (Choose one answer)

A.

The device is blocked from accessing the network.

B.

The device is placed into the onboarding VLAN.

C.

The device is placed into the quarantine VLAN.

D.

The device is assigned to the default management VLAN.

Full Access
Question # 16

How does FortiGate handle configuration of flow tracking sampling if you export the settings to a managed FortiSwitch stack with sampling mode set to perimeter is true?

A.

FortiGate configures FortiSwitch to perform ingress sampling on all switch interfaces.

B.

FortiGate configures FortiSwitch to perform ingress sampling on all switch interfaces, except ICL and ISL interfaces.

C.

FortiGate configures and enables flow sampling on FortiSwitch but does not change existing sampling settings of interfaces.

D.

FortiGate configures and enables egress sampling on all management interfaces.

Full Access
Question # 17

You are deploying a new FortiSwitch device in a branch office and you want it to be automatically detected and managed by FortiGate. Which FortiSwitch feature enables automatic detection during deployment? (Choose one answer)

A.

Zero-touch deployment

B.

Auto-discovery

C.

Link Layer Discovery Protocol (LLDP)

D.

FortiLink heartbeat

Full Access
Question # 18

(Full question statement start from here)

A FortiGate is connected to a pair of FortiSwitch devices.

For redundancy, FortiGate must use uplinks on both switches simultaneouslywithout depending on Spanning Tree Protocol (STP).

Which configuration is required? (Choose one answer)

A.

Multi-tier topology

B.

Multichassis link aggregation group (MCLAG)

C.

Full mesh high availability (HA)

D.

Link aggregation group (LAG)

Full Access
Question # 19

Refer to the exhibit.

The command diagnose switch physical-ports summary is executed on FortiSwitch.

Based on the VLAN assignments shown in the output, what is the most likely management configuration of this FortiSwitch? (Choose one answer)

A.

FortiSwitch is managed by FortiSwitch Cloud.

B.

FortiSwitch is managed by FortiGate.

C.

FortiSwitch is operating in standalone mode.

D.

FortiSwitch is operating in local mode.

Full Access
Question # 20

In which two ways can you assign a FortiSwitch port to a VDOM using multi-tenancy setup? (Choose two.)

A.

Switch the FortiLink interface to the target VDOM.

B.

Remove the managed FortiSwitch and allocate ports directly on FortiSwitch.

C.

Create a virtual port pool on the FortiGate CLI.

D.

Assign a port to a VDOM directly on the managed FortiSwitch.

Full Access
Question # 21

Which two statements about 802.1X authentication on FortiSwitch ports are true? (Choose two.)

A.

All hosts behind an authenticated port are allowed access after a successful authentication.

B.

A security policy is used to apply 802.1 authentication on a port.

C.

A local user database must be used to authenticate devices using the 802.1X authentication protocol.

D.

All devices connecting to FortiSwitch must support 802.1X authentication.

Full Access
Question # 22

Which drop policy mode, if assigned to a congested port, will drop incoming packets until there is no congestion on the egress port?

A.

Tail-drop mode

B.

Weighted round robin mode.

C.

Random early detection mode

D.

Strict mode

Full Access
Question # 23

You are designing a multi-tenant network using FortiSwitch devices in standalone mode. Security is a priority and each tenant’s servers must be completely isolated from one another, and from all other servers in the network, to prevent lateral communication. However, all servers must have access to the shared FortiGate firewall for internet access. Which type of private VLAN (PVLAN) configuration should you apply to meet these security requirements? (Choose one answer)

A.

Standalone VLAN

B.

Community VLAN

C.

Isolated VLAN

D.

Primary VLAN

Full Access
Question # 24

Refer to the exhibits

Traffic arriving on port2 on FortiSwitch is tagged with VLAN ID 10 and destined for PC1 connected on port1. PC1 expects to receive traffic untagged from port1 on FortiSwitch. Which two configurations can you perform on FortiSwitch to ensure PC1 receives untagged traffic on port1? (Choose two.)

A.

Add the MAC address of PC1 as a member of VLAN 10.

B.

Add VLAN ID 10 as a member of the untagged VLANs on port1.

C.

Remove VLAN 10 from the allowed VLANs and add it to untagged VLANs on port1.

D.

Enable Private VLAN on VLAN 10 and add VLAN 20 as an isolated VLAN.

Full Access
Question # 25

In which two ways can you assign a FortiSwitch port to a VDOM using a multi-tenancy setup? (Choose two answers)

A.

Assign the switch port to a VLAN on FortiGate and perform VDOM mapping.

B.

Create a virtual port pool on the FortiGate CLI.

C.

Assign a port to a VDOM directly on the managed FortiSwitch.

D.

Switch the FortiLink interface to the target VDOM.

Full Access
Question # 26

(Full question statement start from here)

What is one key advantage of using a sniffer profile on FortiSwitch compared to using the sniffer command? (Choose one answer)

A.

It allows packet capture on all switch ports without limitations.

B.

It eliminates the need to use access control lists (ACLs) or port mirroring for analysis.

C.

It automatically filters irrelevant traffic types.

D.

It automatically decrypts SSL/TLS traffic for full packet inspection.

Full Access
Question # 27

What are two reasons why time synchronization between FortiGate and its managed FortiSwitch is critical in switch management? (Choose two.)

A.

FortiSwitch does not retain its time after a reboot, which gets reset after each reboot.

B.

FortiSwitch will not be able to become an NTP server for downstream devices.

C.

FortiSwitch cannot complete the DTLS handshake used in the CAPWAP tunnel.

D.

FortiSwitch will not allow other FortiSwitch devices in the chain be discovered by FortiGate.

Full Access
Question # 28

What are two ways in which automatic MAC address quarantine works on FortiSwitch? (Choose two.)

A.

FortiSwitch supports only by VLAN quarantine mode.

B.

FortiGate applies the quarantine-related configuration only on FortiGate.

C.

FortiAnalyzer with a threat detection services license is required.

D.

MAC address quarantine can be enabled through the FortiGate CLI only.

Full Access
Question # 29

Refer to the exhibit.

Which two statements best describe what is displayed in the FortiLink debug output shown in the exhibit? (Choose two.)

A.

FortiSwitch is sending FortiLink heartbeats to FortiGate.

B.

FortiSwitch is discovered and authorized by FortiGate.

C.

FortiSwitch is in a waiting state to join the stack group on FortiGate.

D.

FortiSwitch is ready to push its new hostname to FortiGate.

Full Access
Question # 30

Which two statements about the FortiLink authorization process are true? (Choose two.)

A.

The administrator must manually pre-authorize FortiGate on FortiSwitch by adding the FortiGate serial number.

B.

FortiSwitch requires a reboot to complete the authorization process.

C.

A FortiLink frame is sent by FortiGate to FortiSwitch to complete the authorization.

D.

FortiLink authorization sets the FortiSwitch management mode to FortiLink.

Full Access
Question # 31

Refer to the exhibit.

After reviewing the CLI command output, which two conclusions can you make about the Dynamic Host Configuration Protocol (DHCP) snooping configuration? (Choose two answers)

A.

DHCP snooping is disabled globally.

B.

All ports are untrusted, except port2.

C.

Option 82 is enabled on VLAN 10.

D.

DHCP broadcasts are not restricted.

Full Access
Question # 32

(Full question statement start from here)

Refer to the exhibits.

You enable Dynamic Host Configuration Protocol (DHCP) snooping on the VLAN,Student. The Linux-Client VM sends DHCP requests, and tcpdump confirms the broadcasts. However, the Linux-Server VM, acting as a DHCP server, receives no DHCP traffic. What is the most likely cause of this intra-VLAN traffic being blocked? (Choose one answer)

A.

The DHCP requests are being sent on the wrong VLAN.

B.

Port1 is configured as an untrusted port.

C.

Port4 is not configured as a trusted port.

D.

The Student VLAN must be configured as an allowed VLAN on port1.

Full Access
Question # 33

Refer to the exhibit.

The FortiSwitch CLI output of the diagnose switch-controller switch-info poe summary command for the switch Access-1 is shown. It shows that two ports have Power over Ethernet (PoE) enabled and are already in use. What is the most important consideration if you want to connect additional PoE devices to FortiSwitch? (Choose one answer)

A.

All plugged devices use the same PoE standard: 802.3af/at.

B.

The FortiSwitch model supports the number of PoE devices that you want to connect.

C.

The PoE power mode matches the PoE standard of the device.

D.

The total PoE consumption must not exceed the FortiSwitch power budget.

Full Access
Question # 34

Which QoS mechanism maps packets with specific CoS or DSCP markings to an egress queue?

A.

Queuing for egress traffic

B.

Classification for ingress traffic

C.

Rate limiting for egress traffic

D.

Marking for ingress traffic

Full Access